CVE-2018-0949Microsoft Internet Explorer 10 vulnerability

4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
24.7%
top 3.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 13

Description

A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5microsoft/internet_explorer_9Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2+1
CVEListV5microsoft/internet_explorer_10Windows Server 2012
CVEListV5microsoft/internet_explorer_1118 versions+17

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cf5q-23qm-9wq6: A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Exp2022-05-13
CVEList
CVE-2018-0949: A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Exp2018-07-11

📋Vendor Advisories

1
Microsoft
Internet Explorer Security Feature Bypass Vulnerability2018-07-10
CVE-2018-0949 — Microsoft vulnerability | cvebase